CVE-2025-42966
- EPSS 0.07%
- Published 08.07.2025 00:36:13
- Last modified 08.07.2025 16:18:14
SAP NetWeaver XML Data Archiving Service allows an authenticated attacker with administrative privileges to exploit an insecure Java deserialization vulnerability by sending a specially crafted serialized Java object. This could lead to high impact o...
CVE-2025-42964
- EPSS 0.07%
- Published 08.07.2025 00:35:53
- Last modified 08.07.2025 16:18:14
SAP NetWeaver Enterprise Portal Administration is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host...
CVE-2025-42963
- EPSS 0.07%
- Published 08.07.2025 00:35:45
- Last modified 08.07.2025 16:18:14
A critical vulnerability in SAP NetWeaver Application server for Java Log Viewer enables authenticated administrator users to exploit unsafe Java object deserialization. Successful exploitation can lead to full operating system compromise, granting a...
CVE-2025-42961
- EPSS 0.03%
- Published 08.07.2025 00:35:26
- Last modified 08.07.2025 16:18:14
Due to a missing authorization check in SAP NetWeaver Application server for ABAP, an authenticated user with high privileges could exploit the insufficient validation of user permissions to access sensitive database tables. By leveraging overly perm...
CVE-2025-42959
- EPSS 0.16%
- Published 08.07.2025 00:35:03
- Last modified 08.07.2025 16:18:14
An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential, extracted from a system missing specific security patches, is reused in a replay attack against a different system. Even if the target sy...
CVE-2025-42953
- EPSS 0.06%
- Published 08.07.2025 00:34:41
- Last modified 08.07.2025 16:18:14
SAP Netweaver System Configuration does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This could completely compromise the integrity and availability with no impact on confidentiality of ...
CVE-2025-42989
- EPSS 0.06%
- Published 10.06.2025 00:12:16
- Last modified 12.06.2025 16:06:39
RFC inbound processing�does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation the attacker could critically impact both integrity and availability of the applicatio...
CVE-2025-31325
- EPSS 0.09%
- Published 10.06.2025 00:10:30
- Last modified 12.06.2025 16:06:39
Due to a Cross-Site Scripting vulnerability in SAP NetWeaver (ABAP Keyword Documentation), an unauthenticated attacker could inject malicious JavaScript into a web page through an unprotected parameter. When a victim accesses the affected page, the s...
CVE-2025-42999
- EPSS 21.54%
- Published 13.05.2025 00:17:43
- Last modified 16.05.2025 19:44:49
SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the hos...
CVE-2025-31329
- EPSS 0.06%
- Published 13.05.2025 00:16:51
- Last modified 13.05.2025 19:35:25
SAP NetWeaver is vulnerable to an Information Disclosure vulnerability caused by the injection of malicious instructions into user configuration settings. An attacker with administrative privileges can craft these instructions so that when accessed b...